Mageia 2021-0578: thrift/golang-github-apache-thrift security update
Summary
Malicious RPC clients could send short messages which would result in a
large memory allocation, potentially leading to denial of service.
References
- https://bugs.mageia.org/show_bug.cgi?id=28380
- https://www.openwall.com/lists/oss-security/2021/02/11/2
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13949
Resolution
MGASA-2021-0578 - Updated thrift/golang-github-apache-thrift packages fix security vulnerability
SRPMS
- 8/core/thrift-0.14.0-1.mga8
- 8/core/golang-github-apache-thrift-0.14.0-1.mga8